Who changed this Azure resource, and when
One feed of every change in your tenant — resources, policy, roles and privileged access. Filter it by anything on the row. No query language.
- Every administrative write, in one feed.
- Failed attempts are kept — a denied delete is exactly the row you want.
- Platform noise is hidden by default, never deleted.
- Every filter lives in the URL, so the view you are looking at is a link you can paste into a ticket.
Actor and grantee are different people, and both are recorded